{"id":"CVE-2023-34049","aliases":["PYSEC-2026-1892"],"url":"https://o3.security/vulnerability/CVE-2023-34049","summary":"Salt preflight script could be attacker controlled","details":"The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH runs their script with the privileges of the user running Salt-SSH. Do not make the copy path on the target predictable and ensure we check return codes of the scp command if the copy fails.","published":"2024-11-14T06:30:45Z","modified":"2026-07-07T17:57:27.070604061Z","cvss":{"score":6.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"salt","fixedVersion":"3005.4"},{"ecosystem":"PyPI","name":"salt","fixedVersion":"3006.4"}],"fix":{"url":"https://github.com/saltstack/salt/commit/286d55eb5a6e6bf9428405bdf5632b419bdf8444","label":"saltstack/salt@286d55e"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34049"},{"type":"WEB","url":"https://github.com/saltstack/salt/commit/286d55eb5a6e6bf9428405bdf5632b419bdf8444"},{"type":"WEB","url":"https://github.com/saltstack/salt/commit/7a14112f2a16ce70e3c3e1862c92e37af5f2c7a4"},{"type":"PACKAGE","url":"https://github.com/saltstack/salt"},{"type":"WEB","url":"https://saltproject.io/security-announcements/2023-10-27-advisory"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:27.070604061Z"}}